ThreatSynop[verified]@ThreatSynopDisclosure
A critical unauthenticated SQL injection (CVE‑2025‑26385) in Johnson Controls industrial control systems has been disclosed, with a CVSS score of 10.0 and recommended mitigations such as isolation, patching, and VPN hardening. No public exploitation has been reported yet.
The Daily Tech Feed[verified]@dailytechonxDisclosure
The post announces a critical SQL injection vulnerability (CVE-2025-26385) in Johnson Controls products and urges immediate protection measures for critical infrastructure.
趣テクノロジー[verified]@omomuki_techDisclosure
Johnson Controls’ industrial control products have a critical SQL injection flaw (CVE‑2025‑26385) with a CVSS score of 10.0, stemming from unsanitized inputs that could allow remote attackers to execute arbitrary SQL commands.
CCB Alert@CCBalertPatch
A critical remote command injection vulnerability (CVE‑2025‑26385) in Johnson Controls Metasys SQL Express, with a CVSS score of 9.5, is disclosed and mitigations are available via the provided link.
VaultEdge IT Solutions@VaultEdgeITPatch
Johnson Controls products are vulnerable to a critical SQL injection (CVE-2025-26385); CISA recommends isolation and patching.
CVE@CVEnewDisclosure
The post announces CVE-2025-26385 as a command injection vulnerability affecting Johnson Controls Metasys components, providing a link to the CVE record for further details.
0day Signal@0dayPublishingDisclosure
The text announces CVE‑2025‑26385, detailing a command injection flaw in Johnson Controls Metasys BMS that permits unauthenticated remote SQL execution, and links to a source likely providing further information.